CVE-2022-1209
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
Affected (1)
Products: Ultimatemember: Ultimate Member
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.3.1 |
References (10)
Source: security@wordfence.com
ExploitThird Party Advisory
Source: security@wordfence.com
ExploitIssue TrackingThird Party Advisory
Source: security@wordfence.com
Third Party Advisory
Source: security@wordfence.com
Source: security@wordfence.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.